Junglewise Threat Intelligence

CVE-2026-48617: Node.js Permission Model bypass in process.report.writeReport

CVE-2026-48617 · Severity: low · CVSS 1.8 · Published 2026-06-18

Executive brief

A security flaw in Node.js could allow an attacker to bypass restricted file system permissions. Node.js is a popular runtime environment used to build and run server-side applications. If exploited, this vulnerability allows a user to write diagnostic reports to locations on the server that should be restricted, potentially leading to unauthorized data modification or security policy bypass.

Technical details

A vulnerability in the Node.js Permission Model enforcement allows for a bypass via path misvalidation in the `process.report.writeReport()` function. The root cause is improper validation of file paths when generating diagnostic reports, which can be exploited to write files outside of the intended security boundary. This requires local access with high privileges and specific user interaction under a high-complexity attack scenario. The issue affects Node.js versions 22, 24, and 26, and has been addressed in security releases v22.23.0, v24.17.0, and v26.3.1.

Affected products

  • Node.js Node.js 22.x, 24.x, 26.x

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: patched
  • 2026-06-18: advisory

References